{"id":"CVE-2026-22179","aliases":["GHSA-9p38-94jf-hgjj"],"url":"https://o3.security/vulnerability/CVE-2026-22179","summary":"OpenClaw < 2026.2.22 - Allowlist Bypass via Command Substitution in system.run","details":"OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute non-allowlisted commands by exploiting improper parsing of command substitution tokens. Attackers can craft shell payloads with command substitution syntax within double-quoted text to bypass security restrictions and execute arbitrary commands on the system.","published":"2026-03-18T01:34:23.197Z","modified":"2026-08-07T11:50:37.991909135Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.2.22"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/90a378ca3a9ecbf1634cd247f17a35f4612c6ca6","label":"openclaw/openclaw@90a378c"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22179.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-9p38-94jf-hgjj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22179"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-allowlist-bypass-via-command-substitution-in-system-run"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/90a378ca3a9ecbf1634cd247f17a35f4612c6ca6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:37.991909135Z"}}